Failed Certified in Cybersecurity (CC)? Here's Your Recovery Plan
Failing an exam doesn't define you. The Certified in Cybersecurity (CC) has a pass rate of Not published, you're not alone. Here's exactly what to do next.
The Certified in Cybersecurity (CC) has a pass rate of Not published, which means many qualified candidates don't pass on their first attempt. This is a medium-difficulty exam that challenges even experienced professionals.
Most people who fail and try again with a better strategy pass on their second attempt. The key is understanding what went wrong and fixing it.
Wait Period
30 test-free days after the first attempt, 60 test-free days after the second, and 90 test-free days after the third and every attempt after that
Retake Cost
The full exam fee again, U.S. $199 in the Americas and Asia Pacific, unless you purchased Exam Peace of Mind Protection which includes two attempts inside a 180-day window
Max Attempts
Up to 4 attempts within a 12-month period for each ISC2 certification programme
Pro tip: Rescheduling an appointment costs U.S. $50 and cancelling costs U.S. $100. A standard exam purchase must be scheduled and taken within 365 days; a Peace of Mind purchase shortens that window to 180 days for both attempts. Failing candidates receive a proficiency level for each domain at the test centre, which is the only diagnostic ISC2 provides for planning a retake.
- Studying the 2022 domain list because a free course still teaches itThe outline changes on September 1, 2026, and from that date Business Continuity, Disaster Recovery and Incident Response is no longer a domain. Check that your material covers Security Governance and Identity and Access Management Concepts by name, and that Domain 5 includes threat intelligence and incident response.
- Assuming the free One Million Certified in Cybersecurity course and exam are still availableISC2 closed new enrolments on May 20, 2026. Only codes issued before then are still usable, and they must be used to schedule and sit an exam by December 31, 2026. A new candidate pays U.S. $199.
- Planning to flag hard items and return to themCC is adaptive and item review is not permitted. Once you finalise an answer, it is locked. Read each item completely the first time, make your decision, and move on, because there is no second pass.
- Panicking because every question feels difficultISC2 states that the algorithm targets items you have roughly a 50 percent chance of answering correctly, so both strong and weak candidates find the later items hard. Difficulty during the exam carries no information about your result.
- Rushing to finish at 100 itemsThe exam ends when the algorithm reaches 95 percent confidence, not when you reach a target count. Candidates who pass at exactly 100 items proved proficiency across all domains; going past 100 simply gives the algorithm more evidence. Speed does not help.
- Running out of time before answering 100 itemsIf you do not answer 75 operational items and 25 pretest items inside the two hours, ISC2 automatically fails the exam. Breaks count against the two hours. Keep a pace of roughly 70 seconds per item and check the clock every 20 items.
- Treating cloud security as optional because CC is entry levelCloud security is a named sub-objective inside Domain 4, which carries 21.3 percent of the exam. The outline asks for cloud characteristics, service models, deployment models, and the shared security model, so learn all four lists rather than one.
- Skimming the ISC2 Code of EthicsThe Code of Ethics is a named bullet in Domain 1, and you must also confirm you will abide by it to complete the certification application. Learn the four canons and their order, because questions ask which canon applies to a described situation.
- Registering with a name that does not match your IDThe first and last name on your ID must exactly match your Pearson VUE registration. Names can be updated up to 48 hours before the appointment and cannot be changed at the test centre. A mismatch is recorded as a no-show and forfeits the fee.
- Passing the exam and then doing nothingPassing does not make you certified. Submit the certification application at the ISC2 endorsement portal within nine months of the exam pass date, confirm the Code of Ethics, then pay the U.S. $50 annual maintenance fee to start your membership cycle.
Analyze Your Score Report
Review your Certified in Cybersecurity (CC) score report immediately. Identify which domains you scored lowest in, these are your priority areas. Write down specific topics you struggled with while the exam is fresh in your memory.
Take a Short Break (But Not Too Long)
Take 2-3 days off from studying to reset mentally. Failing is emotionally draining, and jumping back in immediately can lead to burnout. But don't wait too long, the material is still fresh.
Change Your Study Strategy
Whatever approach you used before didn't work. Switch it up: if you only read textbooks, add video courses. If you didn't do practice tests, make them your primary study method. Active recall beats passive review every time.
Focus on Weak Areas (80/20 Rule)
Spend 80% of your study time on the 2-3 domains where you scored lowest. You probably already know the topics you scored well on. For Certified in Cybersecurity (CC), this targeted approach is far more effective than re-studying everything.
Take a Practice Test Before Rebooking
Don't rebook the exam until you're consistently scoring 85%+ on practice tests. This saves you money and builds real confidence. When you're scoring well, schedule the retake.
- Sitting after 1 Sept 2026 means the new outline
- Learn the five new domain names: Security Principles, Security Governance, IAM Concepts, Networking and Cloud Security, Security Operations and Incident Response
- The exam is adaptive, so answer every item carefully because you cannot go back and change one
- Budget the full 120 minutes for at least 100 items, which is about 70 seconds each
- Memorise the ISC2 Code of Ethics canons in order, since Domain 1 names them explicitly
- Bring two forms of ID and expect a palm vein scan at the Pearson VUE test centre
How long do I have to wait to retake the Certified in Cybersecurity (CC)?
The retake waiting period for Certified in Cybersecurity (CC) is 30 test-free days after the first attempt, 60 test-free days after the second, and 90 test-free days after the third and every attempt after that. Rescheduling an appointment costs U.S. $50 and cancelling costs U.S. $100. A standard exam purchase must be scheduled and taken within 365 days; a Peace of Mind purchase shortens that window to 180 days for both attempts. Failing candidates receive a proficiency level for each domain at the test centre, which is the only diagnostic ISC2 provides for planning a retake.
How much does it cost to retake the Certified in Cybersecurity (CC)?
The retake cost is The full exam fee again, U.S. $199 in the Americas and Asia Pacific, unless you purchased Exam Peace of Mind Protection which includes two attempts inside a 180-day window. Maximum attempts: Up to 4 attempts within a 12-month period for each ISC2 certification programme.
What percentage of people fail the Certified in Cybersecurity (CC)?
The Certified in Cybersecurity (CC) has an average pass rate of Not published, meaning roughly a significant percentage of test-takers fail on their first attempt.
Is the Certified in Cybersecurity (CC) harder the second time?
No, the Certified in Cybersecurity (CC) difficulty is the same on retake. Many people pass on their second attempt because they know what to expect and can focus their study on weak areas.
Ready to pass Certified in Cybersecurity (CC)?
Get the complete exam guide with study plan, resources, and expert tips.
View Certified in Cybersecurity (CC) Guide